← Vulnerability feed

Vulnerability record · CVE-2018-1323 · published 12 March 2018

CVE-2018-1323: Apache Tomcat JK ISAPI Connector path normalization bypass exposes hidden apps

Apache · Tomcat Jk Connector

The IIS/ISAPI-specific code in Apache Tomcat JK ISAPI Connector 1.2.0 through 1.2.42 normalized request paths before matching them to the URI-worker map and mishandled some edge cases. When only a subset of Tomcat URLs was exposed through IIS, a crafted request could reach application functionality not intended to be reachable through the reverse proxy.

7.5 CVSS 3.0 High EPSS 46% · top 1.2% CWE-22 · Path traversalCWE-200 · Information exposure
7.5CVSS 3.0 base score, v2 5.0
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the reverse proxy.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 7.5 with network reachability and no authentication required, plus a high EPSS percentile, makes this a serious exposure risk despite no confirmed in-the-wild exploitation.

What it is

The IIS/ISAPI-specific code in Apache Tomcat JK ISAPI Connector 1.2.0 through 1.2.42 normalized request paths before matching them to the URI-worker map and mishandled some edge cases. When only a subset of Tomcat URLs was exposed through IIS, a crafted request could reach application functionality not intended to be reachable through the reverse proxy.

Impact

An unauthenticated remote attacker can bypass the intended reverse-proxy URL restrictions and reach Tomcat application endpoints that were meant to be hidden, gaining access to functionality or data behind the proxy.

Attack surface

Reached over the network via HTTP requests to an IIS server fronting Tomcat with the JK ISAPI Connector; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.46397 (98.8th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade the Apache Tomcat JK ISAPI Connector to a version later than 1.2.42 that contains the fix.
  • Apply vendor errata such as Red Hat RHSA-2018:1843 where the connector is packaged.
  • Review and tighten the URI-worker map so only explicitly required Tomcat URLs are proxied.
  • Restrict network access to the IIS/ISAPI front end so only trusted clients can reach it.

Detection

  • Inspect IIS and JK connector logs for requests containing encoded or unusual path sequences (e.g., %2e, %2f, double slashes) that resolve to non-exposed URIs.
  • Baseline the set of URIs normally served through the connector and alert on requests to paths outside that baseline.
  • Monitor for HTTP requests reaching Tomcat application endpoints that are not in the intended exposed URL list.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/103389 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:1843 Third Party Advisory
https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/6e146bce83578bd870893250ba8354e28f9d8e86c674c30dbeee529f%40%3Cannounce.tomcat.apach
https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.or
https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.or
http://www.securityfocus.com/bid/103389 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:1843 Third Party Advisory
https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/6e146bce83578bd870893250ba8354e28f9d8e86c674c30dbeee529f%40%3Cannounce.tomcat.apach
https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.or
https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.or

Track CVE-2018-1323 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-6808Apache tomcat jk connector memory buffer overflow vulnerabilityBuffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.EPSS 23%7.5CVE-2018-11759Apache Tomcat JK Connector path normalization flaw allows proxy bypassThe Apache httpd-specific path normalization code in Apache Tomcat JK (mod_jk) Connector 1.2.0 through 1.2.44 mishandled certain edge cases before ma…EPSS 91%analysed9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed10.0CVE-2026-34909UniFi OS path traversal allows unauthenticated file accessUniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the expos…KEVEPSS 1.8%analysed

Source: NIST National Vulnerability Database (record CVE-2018-1323), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.